Vulnerability Monitor

The vendors, products, and vulnerabilities you care about
orion_platform Vendor: solarwinds

About This Product

orion_platform is a software product offered by solarwinds. This product serves as critical infrastructure in many organizational deployments, making vulnerability monitoring essential for organizations relying on it. Security vulnerabilities in products of this category can affect system availability, data confidentiality, and integrity across entire networks. The moderate vulnerability count reflects ongoing security research and responsible disclosure practices. Regular assessment of known vulnerabilities and timely patching are fundamental components of responsible system administration for any deployment of this software.

Vulnerability Landscape Summary

SecUtils has identified 49 known vulnerabilities affecting solarwinds orion_platform. This includes 5 critical-severity issues and 26 high-severity issues that warrant immediate attention. Vulnerabilities in this product have been disclosed spanning from 2019 to 2023, indicating a recent active security attention. 18 medium-severity issues complete the vulnerability landscape. Organizations should prioritize patching based on deployment context, asset criticality, and exploitation likelihood rather than severity alone.

Known Vulnerabilities
ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2019-9546 2019-03-01 2024-11-21 9.8 7.5 Likely
CVE-2019-17125 2020-01-17 2024-11-21 6.1 4.3 Likely
CVE-2019-17127 2020-01-17 2024-11-21 6.1 4.3 Likely
CVE-2019-12863 2020-02-25 2024-11-21 4.8 3.5 Unknown
CVE-2019-12864 2020-05-04 2024-11-21 5.5 2.1 Unknown
CVE-2020-13169 2020-09-17 2024-11-21 9.0 3.5 Unknown
CVE-2020-10148 2020-12-29 2025-10-24 9.8 7.5 Likely
CVE-2021-25274 2021-02-03 2024-11-21 9.8 10.0 Likely
CVE-2021-25275 2021-02-03 2024-11-21 7.8 2.1 Unknown
CVE-2020-27870 2021-02-10 2024-11-21 6.5 4.0 Likely
CVE-2020-27871 2021-02-10 2024-11-21 7.2 9.0 Likely
CVE-2020-35856 2021-03-26 2024-11-21 4.8 3.5 Unknown
CVE-2021-3109 2021-03-26 2024-11-21 4.8 4.9 Unknown
CVE-2021-27258 2021-04-14 2024-11-21 9.8 7.5 Likely
CVE-2021-27277 2021-04-22 2024-11-21 7.8 7.2 Unknown
CVE-2021-28674 2021-07-30 2024-11-21 5.4 5.5 Likely
CVE-2021-35219 2021-08-31 2024-11-21 6.0 4.0 Likely
CVE-2021-35220 2021-08-31 2024-11-21 8.1 6.5 Likely
CVE-2021-35221 2021-08-31 2024-11-21 6.3 5.5 Likely
CVE-2021-35222 2021-08-31 2024-11-21 8.0 4.3 Likely
CVE-2021-35213 2021-08-31 2024-11-21 8.9 9.0 Likely
CVE-2021-35239 2021-08-31 2024-11-21 7.5 3.5 Unknown
CVE-2021-35240 2021-08-31 2024-11-21 6.5 3.5 Unknown
CVE-2021-35212 2021-08-31 2024-11-21 8.9 9.0 Likely
CVE-2021-35238 2021-09-01 2024-11-21 4.8 3.5 Unknown
CVE-2021-35215 2021-09-01 2024-11-21 8.9 6.5 Likely
CVE-2021-35218 2021-09-01 2024-11-21 8.9 6.5 Likely
CVE-2021-35234 2021-12-20 2024-11-21 8.0 6.5 Likely
CVE-2021-35244 2021-12-20 2024-11-21 6.8 8.5 Unknown
CVE-2021-35248 2021-12-20 2024-11-21 6.8 4.0 Likely
CVE-2022-36961 2022-09-30 2024-11-21 8.8 - -
CVE-2022-36957 2022-10-20 2024-11-21 7.2 - -
CVE-2022-36958 2022-10-20 2024-11-21 8.8 - -
CVE-2022-36966 2022-10-20 2025-05-07 5.4 - -
CVE-2022-38108 2022-10-20 2025-05-08 7.2 - -
CVE-2022-36960 2022-11-29 2024-11-21 8.8 - -
CVE-2022-36962 2022-11-29 2024-11-21 7.2 - -
CVE-2022-36964 2022-11-29 2024-11-21 8.8 - -
CVE-2022-38111 2023-02-15 2024-11-21 7.2 - -
CVE-2022-47503 2023-02-15 2024-11-21 7.2 - -
CVE-2022-47504 2023-02-15 2024-11-21 7.2 - -
CVE-2022-47506 2023-02-15 2024-11-21 7.8 - -
CVE-2022-47507 2023-02-15 2024-11-21 7.2 - -
CVE-2023-23836 2023-02-15 2024-11-21 7.2 - -
CVE-2022-36963 2023-04-21 2024-11-21 7.2 - -
CVE-2022-47505 2023-04-21 2024-11-21 7.8 - -
CVE-2022-47509 2023-04-21 2024-11-21 6.1 - -
CVE-2023-23840 2023-09-13 2024-11-21 6.8 - -
CVE-2023-23845 2023-09-13 2024-11-21 6.8 - -

How SecUtils Interprets Product Data

SecUtils normalizes and enriches National Vulnerability Database (NVD) records for solarwinds orion_platform by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and structuring the data for rapid analysis and asset correlation. For every vulnerability listed, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference information to enable organizations to prioritize patching and risk assessment efficiently. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for vulnerability management and security operations.